Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

The Convergence of eBPF, Buildroot, and QEMU for Automated Linux Malware Analysis

nullcon via YouTube

Overview

Limited-Time Offer: Up to 75% Off Coursera Plus!
7000+ certificate courses from Google, Microsoft, IBM, and many more.
This course covers the learning outcomes and goals of conducting in-depth analysis of Linux-based malware such as Mirai and AvosLocker. It teaches the principles of extended Berkeley Packet Filter (eBPF) for tracing and observability, utilizing Buildroot to develop Linux sandboxes, and employing QEMU for emulation. The teaching method includes a talk with a speaker introduction, agenda overview, eBPF principles explanation, ELFEN sandbox demonstration, and future work discussion. The intended audience for this course includes cybersecurity professionals, malware analysts, and individuals interested in Linux malware analysis.

Syllabus

Speaker and Talk Introduction
Talk Agenda
extended Berkeley Packet Filter eBPF
ELFEN Sandbox
Demo Analysis with ELFEN
Future Work

Taught by

nullcon

Reviews

Start your review of The Convergence of eBPF, Buildroot, and QEMU for Automated Linux Malware Analysis

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.